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IN THE claims? 



1 . (Currently amended) A method, in a computer system, for monitoring data sent 
from a the computer system , comprising: 

detecting a request for an outgoing transfer of data from a program in the 
computer system to a destination; 

determining whether the destination is a trusted site; end 

performing a corrective action if the destination is not a trusted sit e, wherein the 
step of performing a corrective acti on co mprises changing the d estination of th« n,,t^; nf , 
transfer to the computer system, and determi n ing whether the program op erate in 
response t o the changed destination . 

2. (Original) The method of claim 1 , wherein the step of determining whether the 
destination is a trusted site comprises matching the destination against a list of trusted 
sites. 



3. (Original) The method of claim 1 , wherein the corrective action comprises 
blocking the outgoing transfer. 

4. (Currently amended) The method of claim 1 , wherein the corrective action 
comprises disabling the program that requested the outgoing f^fe »f^o 

5. (Cancelled) 



6. (Currently amended) The method of olniiu 1 A method, in a computer system fnr 
monitoring data sent from a computer, comprising; 

detecting a request for an outgoing tra nsfer of data frn m a program in the 
computer system t n a destination ; 

determining whether the destina tion is a busted site: and 
performing a corrective action if the destination , s not a trusts «it« wherein the 
step of performing a corrective action comprises: 
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irrcvoroibly encrypting the data; and 

determining whether the program operates in response to the encryption. 

7. (Currently amended) The method of claim 6, wherein the step of wpeversifeiy 
encrypting the data comprises irreversibly en crypting the data hy injecting random 
numbers into the data. 

8. (Currently amended) The method of oln i m 1, further comp i i^ , A method, in a 
computer system, for monitoring data sent from th e computer svst*m r^ ri^ 

detecting a request for an outgoing transfer o f date from a program in thr. 
computer s ystem to a destination: 

determining whether th e destination is a trusted sj jte; 

performing a corrective actio n if the destination is not a trusted *itr 

determining whether the amount of data for the outgoing transfer is 
uncharacteristically high; and 

performing a corrective action if the amount of data is uncharacteristically high. 

9. (Currently amended) The method of claim 1 , further comprising: 

determining whether the data includes personal information if the destination is a 
trusted site : and 

performing a corrective action if the data includes personal information. 

1 0. (Original) The method of claim 9, wherein the step of determining whether the 
data includes personal information comprises performing a text string search or binary 
pattern search on the data. 

1 1 . (Original) The method of claim 1 , wherein the step of performing a corrective 
action comprises storing a log of the outgoing transfer. 

12. (Original) The method of claim 1 1 , wherein the step of storing a log of the 
outgoing transfer comprises storing the data. 
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13. (Original) The method of Cain, 1 1, norther comprising ^ ^ tQ 

remote computer. 

K (Current tended) A me,hod, i„ . ^ fc m()niloiing ^ ^ 

from a the computer system , comprising: 

detecting a request for an outgoing transfer of data from a program in the 
computer system to a destination; 

determining whether the amount of the data is uncharacteristical.y high; and 
high Peif0m,ln8 3 CO,TeCtiVe aCti0 " ^ ^ 3m0Unt ° fthe data is "ncharacteristically 

15. (Original) The method of claim 14, wherein the corrective action comprises 

blocking the data transfer. 

16. (Currently amended) The method of claim 14, wherein the corrective action 
composes disabling the program that rem^ th.„.., roing nfAmtm 

1 7. (Original) The method of claim 14, wherein the step of performing a corrective 

action comprises: 

changing the destination of the outgoing transfer to the computer system; and 
determining whether the program operates in response to the changed destination. 

1 8. (Original) The method of claim 14, wherein the step of performing a corrective 
action comprises; 

irreversibly encrypting the data; and 

determining whether the program operates in response to the encryption. 

19. (Original) The method of claim 1 8, wherein the step of irreversibly encrypting the 
data comprises injecting random numbers into the data. 
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20. (Original) The method of claim 14, further comprising: 
determining whether the data includes personal information; and 
performing a corrective action if the data includes personal information. 

21 . (Original) The method of claim 20, wherein the step of determining whether u . 
data mcludes personal information comprises performing a text string search or binary 
pattern search on the data. 



the 



22. (Original) The method of claim 14, wherein the step of performing a corrective 
action comprises storing a log of the outgoing transfer. 

23. (Original) The method of claim 22, wherein the step of storing a log of the 
outgoing transfer comprises storing the data. 

24. (Original) The method of claim 22, further comprising transferring the log to a 
remote computer 

25. (Currently amended) An apparatus for monitoring data sent from a computer 
system, comprising: 

detection means for detecting a request for an outgoing transfer of data from a 

program in the computer system to a destination; 

determination means for determining whether the destination is a trusted site; and 
correction means for performing a corrective action if the destination is not a 

trusted sitei 

means for determining whether the data inri,^ nal infemwtinn if 
destination is * te sted site: and 

means for pertormin? the corrective acH™ if , he data inr |„rf PC pOT ,^i 
information . 

26. (Original) The apparatus of claim 25, wherein the determination means comprises 
means for matching the destination against a list of trusted sites. 
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